Comments (1)
I am running into the same problem, also with AWS Cognito. Took me quite a while before I found out that the iat
was causing our tests to fail.
I am not sure whether verification of the iat
timestamp is even the right way to go. The JWT spec says nothing about how iat
should be verified. In case issue dates should be verified, nbf
seems more appropriate. The spec also allows for a small leeway to account for clock skew.
A relevant discussion around this topic can be found at auth0/java-jwt#254.
from fastapi-cloudauth.
Related Issues (20)
- Cannot access `/users/` using the AWS Cognito configuration HOT 2
- Firebase - Unauthenticated request is not raising an exception HOT 1
- Standalone function to verify token
- firebase.JWKS public keys expire and don't get refreshed HOT 2
- Add ability to specify `user_info` as an extra parameter when instantiating `UserInfoAuth` derived classes HOT 1
- "not verified" response - cognito HOT 5
- Enfore that a user's e-mail is verified in Auth0 for accessing an API
- Clarification on Role Based Access Control (RBAC) using firebase auth HOT 1
- cognito: "Validation Error for Claims" - when using custom attributes in cognito HOT 1
- How to catch exception or change the Scope not matched message
- Simple Auth0 authentication when using the doc or redoc page
- [Cognito] App client_id is not validated for Cognito JWT (access_token)
- Take lot of time to start a fastapi project
- Having trouble figuring out "next steps" HOT 1
- How can I get the groups/scopes a user is associated in Cognito? HOT 1
- Feature: Add scopes required to the openapi docs
- How can we make it possible to enable Authentication for Websockets?
- how to add google login?
- Specify to work with localstack or Cognito Local for local testing?
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from fastapi-cloudauth.